Radu Tudorica. (2021, July 12). A Fresh Look at Trickbot’s Ever-Improving VNC Module. Retrieved September 28, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.005 VNC |
MalwareTrickBot | TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network |
| T1041 Exfiltration Over C2 Channel |
MalwareTrickBot | TrickBot can send information about the compromised host and upload data to a hardcoded C2 server. |
| T1059.001 PowerShell |
MalwareTrickBot | TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers. |
| T1090.002 External Proxy |
MalwareTrickBot | TrickBot has been known to reach a command and control server via one of nine proxy IP addresses. |
| T1105 Ingress Tool Transfer |
MalwareTrickBot | TrickBot downloads several additional files and saves them to the victim's machine. |
| T1555.003 Credentials from Web Browsers |
MalwareTrickBot | TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl. |
| T1564.003 Hidden Window |
MalwareWarzoneRAT | WarzoneRAT has the ability of performing remote desktop access via a hVNC window for decreased visibility. |
| T1571 Non-Standard Port |
MalwareTrickBot | Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.